Skip to content

feat: Updates for 1.20.1 - #498

Merged
cdesiniotis merged 2 commits into
NVIDIA:mainfrom
mikemckiernan:mmck-cnt-20-1
Sep 18, 2026
Merged

cdesiniotis merged 2 commits into
NVIDIA:mainfrom
mikemckiernan:mmck-cnt-20-1

Conversation

@mikemckiernan

Copy link
Copy Markdown
Member

No description provided.

Signed-off-by: Mike McKiernan <mmckiernan@nvidia.com>
@github-actions

Copy link
Copy Markdown

Documentation preview

https://nvidia.github.io/cloud-native-docs/review/pr-498

@cdesiniotis cdesiniotis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great work as always @mikemckiernan!

Comment thread container-toolkit/cdi-support.md Outdated

JIT-CDI mode injects MIG management capability device nodes when the `NVIDIA_MIG_CONFIG_DEVICES` or `NVIDIA_MIG_MONITOR_DEVICES` environment variable is set to `all` in a privileged container.
This injects the `/dev/nvidia-caps/` device nodes that tools such as `nvidia-smi mig` need to create, destroy, and monitor MIG partitions.
The container must have `CAP_SYS_ADMIN`, and the host must use cgroup v2.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IIRC this change does not depend on cgroup v2, so I would prefer to omit this clause. @henry118 could you confirm?

Suggested change
The container must have `CAP_SYS_ADMIN`, and the host must use cgroup v2.
The container must have `CAP_SYS_ADMIN`.

@henry118 henry118 Sep 17, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Strictly speaking, CAP_SYS_ADMIN is the only requirement here - not even "privileged" container.

Note that when a container is "privileged" (either with --privileged docker CLI option, or privileged: true in k8s pod spec), all devices under /dev will be automatically injected by runtime (containerd) by default, regardless the toolkit.

Comment thread container-toolkit/cdi-support.md Outdated

JIT-CDI mode injects MIG management capability device nodes when the `NVIDIA_MIG_CONFIG_DEVICES` or `NVIDIA_MIG_MONITOR_DEVICES` environment variable is set to `all` in a privileged container.
This injects the `/dev/nvidia-caps/` device nodes that tools such as `nvidia-smi mig` need to create, destroy, and monitor MIG partitions.
The container must have `CAP_SYS_ADMIN`, and the host must use cgroup v2.

@henry118 henry118 Sep 17, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Strictly speaking, CAP_SYS_ADMIN is the only requirement here - not even "privileged" container.

Note that when a container is "privileged" (either with --privileged docker CLI option, or privileged: true in k8s pod spec), all devices under /dev will be automatically injected by runtime (containerd) by default, regardless the toolkit.

Comment thread container-toolkit/docker-specialized.md Outdated
The following command injects both MIG config and monitor devices:

```console
$ docker run --rm --runtime=nvidia --privileged \

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So here it's better to use --cap-add=SYS_ADMIN option instead of --privileged. Since mig config/monitor devices will be always available to the container in the latter case.

Comment thread container-toolkit/release-notes.md Outdated
### Fixes and Features

- CDI specifications and JIT-CDI mode now inject MIG management capability devices into containers.
Set the `NVIDIA_MIG_CONFIG_DEVICES` or `NVIDIA_MIG_MONITOR_DEVICES` environment variable to `all` in a privileged container to inject the `/dev/nvidia-caps/` device nodes for MIG partition management.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here about the "privileged" wording

Signed-off-by: Mike McKiernan <mmckiernan@nvidia.com>
@cdesiniotis
cdesiniotis merged commit 53e1624 into NVIDIA:main Sep 18, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants